Category PS4 Jailbreaking       Thread starter PSXHAX       Start date Apr 21, 2016 at 9:12 PM       11,352       10            
Status
Not open for further replies.
Following news of the PS4 Dlclose Exploit for 1.76 and more recently the Entry Point findings, today Wololo reports that PlayStation 4 developer Fire30 made available on Github a PS4 Webkit Exploit proof-of-concept for PlayStation 4 Firmware 2.XX.

Download: PS4-2014-1303-POC-master.zip / PS4-2014-1303-POC GIT

From the ReadMe file: CVE 2014-1303 Proof Of Concept for PS4

This repository contains a poc for the CVE 2014-1303 originally disclosed by Liang Chen. It has been tested to work on system firmware 2.03, but should work for systems on a firmware < 2.50, the ROP test will however only work on 2.03.

Usage

You need to edit the dns.conf to point to the ip address of your machine, and modify your consoles dns settings to point to it as well. Then run
Code:
python fakedns.py -c dns.conf
then
Code:
python server.py
Debug output will come from this process.

Navigate to the User's Guide page on the PS4 and various information should be printed to the console. The ROP test will print what is stored in the rsp register. Continuing execution after rsp is pivoted still needs to be done.

Acknowledgements

Liang Chen
thexyz
dreadlyei

Fire30 also notes, to quote: This implementation will not work on the vita as it uses a different memory allocator. In fact I am using the same exploit that is used in https://github.com/Hykem/vitasploit for 3.36, so that is the farthest this vulnerability will go.

Thanks to CnCore for the tip in the PSXHAX.COM Shoutbox! :D

CVE-2014-1303.jpg
 

Comments

Status
Not open for further replies.

azoreseuropa

Senior Member
Contributor
Verified
- Badiret patch released on FreeBSD 9 (Orbis) = 2015-08-25
- 2.57 = Jully 2015
A JB may come soon for 2.03 with the dlclose exploit with the help of FIRE30.

A POC has been posted on twitter of POC 3.50 webkit exploit (twit deleted). With a Badiret exploit, there is still hope for a 2.57 (even 3.00 ?) Jailbreak.
I hope so.
 
Status
Not open for further replies.
Recent Articles
PlayStation Store's Totally Digital Sale Live with Savings on PSN Games
Get set to awaken a mysterious power within to save the world in Indivisible, make a daring escape with a little help from a friend in A Way Out or fight your way through the perfect run in the...
PlayStation 5 User Interface (PS5 UI) Rumored Image Leak Surfaces
An image that is rumored to be a screenshot of the current PlayStation 5 User Interface (PS5 UI) has reportedly leaked by an Anonymous game studio employee on the popular 4Chan bulletin board. 🤩...
Frost4 (PS4 Frostbite Engine) Toolkit & GNMF (BA2) Tools by SockNastre
Recently developer SockNastre made available on Github both a Frost4 Toolkit for modifying the proprietary Frostbite engine on PS4 alongside some BethesdaArchive2 GNMF tools to read / write in...
Grand Theft Auto V (GTA V) ArabicGuy Mod Menu for PS4 2020 Demo
Following the ArabicGuy v1.1 GTA V Mod Menu by @RF0oDxM0Dz and the Ghosts 1.00 SilentShadowV3 Mod Menu, PlayStation 4 scene developer @CustomHooker shared on Twitter a new Grand Theft Auto V (GTA...
Top